4 ms·
In my opinion the SSH example with a non default port, random username and easy password is a perfect example of a bad kind of security through obscurity: inste
by resfirestar 6y ago
In my opinion the SSH example with a non default port, random username and easy password is a perfect example of a bad kind of security through obscurity: instead of a user friendly and foolproof approach (disabling password authentication and using keys), we introduce multiple layers of obscurity that make life harder for the sysadmin and users, which collapse as soon as someone creates an account on the box without a sufficiently obscure name. When it inevitably fails (either because of the aforementioned reason or because a global scanner has the clever idea of trying some more obscure usernames) everyone looking back on it will wonder why you built this Rube Goldberg machine instead of just using SSH keys.
Changing the RDP port is a slightly better example of actually using security through obscurity as a defensive layer because Microsoft doesn’t give you any good ways to lock down RDP (best practice is of course keeping it behind a VPN or using a Remote Desktop solution with a more modern authentication system), but from a practical point of view I know several companies that were hit with ransomware this year via RDP on a non-standard port. I think they would rate the risk reduction from that approach pretty low.
Finally, symmetric database encryption is not an obscurity measure, as the author himself points out it specifically protects data against an attacker who can query the database but not find the key. Whether the attacker can get the key is a matter of capability not determination or luck.